Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files...
Automatically fetch Dependabot security alerts from GitHub and update vulnerable packages to secure versions.
Use GitHub REST API to fetch open Dependabot alerts:
# Get repository owner and name from git remote
git remote get-url origin
# Fetch alerts (requires GITHUB_TOKEN)
curl -H "Authorization: token $GITHUB_TOKEN" \
-H "Accept: application/vnd.github+json" \
"https://api.github.com/repos/{owner}/{repo}/dependabot/alerts?state=open"
Or use the GitHub CLI if available:
gh api repos/{owner}/{repo}/dependabot/alerts --jq '.[] | select(.state == "open")'
Required environment variable: GITHUB_TOKEN with security_events scope.
For each alert, extract:
dependency.package.name)security_advisory.severity: critical, high, moderate, low)security_vulnerability.vulnerable_version_range)security_advisory.ghsa_id or security_advisory.cve_id)dependency.manifest_path)Group alerts by:
For each vulnerable package, determine the minimum secure version:
Check alert API response - The security_vulnerability.first_patched_version field often contains the fixed version:
gh api repos/{owner}/{repo}/dependabot/alerts/{alert_number} | jq '.security_vulnerability.first_patched_version'
Search for security advisories:
https://github.com/advisories?query={package}npm audit {package}https://security.snyk.io/package/npm/{package}Web search for CVE details and fixed versions:
{package} {CVE_ID} fixed version{package} {GHSA_ID} fixed versionVerify compatibility:
For monorepos, find all package.json files:
find . -name "package.json" -not -path "*/node_modules/*" -not -path "*/.git/*"
For each vulnerable package found in package.json:
// Before
"package-name": "^1.2.3"
// After (if 1.5.0 fixes the vulnerability)
"package-name": "^1.5.0"
Use ^ prefix to allow patch/minor updates unless major version is required.
If the same package appears in multiple package.json files with different versions:
For peer dependencies, update the package that provides the dependency, not the peer dependency declaration itself.
After updating package.json:
pnpm install to update pnpm-lock.yamlnpm install to update package-lock.jsonyarn install to update yarn.lockNote: Some example directories may have separate lock files that need individual updates.
After updates:
Check remaining alerts:
gh api repos/{owner}/{repo}/dependabot/alerts?state=open
Run audit:
pnpm audit # or npm audit / yarn audit
Test build:
pnpm run build
A Node.js script is provided in scripts/fetch_and_fix_alerts.mjs that automates the workflow:
# Set GitHub token
export GITHUB_TOKEN=your_token_here
# Dry run to see what would be updated
node scripts/fetch_and_fix_alerts.mjs --dry-run
# Actually update packages
node scripts/fetch_and_fix_alerts.mjs
# Or specify repo explicitly
node scripts/fetch_and_fix_alerts.mjs --owner OWNER --repo REPO --token TOKEN
The script:
first_patched_version from API when available)Requirements: Node.js 18+ (uses native fetch API, no external dependencies)
If implementing manually or the script needs customization:
# Pseudocode workflow
alerts = fetch_dependabot_alerts(owner, repo, token)
vulnerable_packages = parse_alerts(alerts)
for package in vulnerable_packages:
secure_version = research_secure_version(package, cve_id)
package_json_files = find_package_json_with_package(package)
for pkg_json in package_json_files:
update_package_version(pkg_json, package, secure_version)
run_package_manager_install()
verify_alerts_resolved()
vitest to latest (includes happy-dom@20.0.2+)Many vulnerabilities (h3, qs, tar-fs, node-forge, glob, jws, ipx, tar, esbuild, http-proxy-middleware, undici, on-headers, tmp, diff) are transitive and will be resolved when direct dependencies are updated.
After processing, provide a summary listing:
pnpm install (or npm install / yarn install)pnpm auditpnpm run buildThe script requires a GitHub token with security_events scope:
Create a Personal Access Token:
security_events scopeSet the token:
export GITHUB_TOKEN=your_token_here
Or use GitHub CLI (alternative):
gh auth login
# Then use: gh api repos/{owner}/{repo}/dependabot/alerts